WordPress vulnerability database

Every CVE published for WordPress core, plugins and themes since January 2024: 29,070 vulnerabilities, 1,395 of them in the last 30 days. The list is updated every day from the CVE List.

Severity is the CVSS 3.1 base score. Select a band to list only those. Last updated October 6, 2026.

Showing 151–200 of 675 vulnerabilities matching your filters

Known WordPress vulnerabilities, page 4 of 1
Severity Component Vulnerability Affected versions Published CVE Source
7.2 High Custom Payment Gateways for WooCommerce Plugin custom-payment-gateways-woocommerce Cross-Site Scripting Unauthenticated Stored Cross-Site Scripting via 'alg_wc_cpg_input_fields' Parameter No login needed ≤ 2.1.0 CVE-2026-7517 Wordfence
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Broken Access Control ≤ 2.7.6 Fixed in 2.7.7 CVE-2026-57332 Patchstack
7.1 High FOX Plugin woocommerce-currency-switcher Cross-Site Scripting No login needed ≤ 1.4.8 Fixed in 1.4.9 CVE-2026-57319 Patchstack
7.5 High Subscriptions for WooCommerce Plugin subscriptions-for-woocommerce Broken Access Control No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2026-56061 Patchstack
7.5 High Print Invoice & Delivery Notes for WooCommerce Plugin woocommerce-delivery-notes Information Disclosure Sensitive Data Exposure No login needed ≤ 7.1.1 Fixed in 7.1.2 CVE-2026-56060 Patchstack
7.1 High Customer Reviews for WooCommerce Plugin customer-reviews-woocommerce Cross-Site Scripting No login needed ≤ 5.110.1 Fixed in 5.111.0 CVE-2026-56043 Patchstack
7.5 High CorvusPay WooCommerce Payment Gateway Plugin corvuspay-woocommerce-integration Authentication Bypass Broken Authentication No login needed ≤ 2.7.4 Fixed in 2.7.5 CVE-2026-56029 Patchstack
7.5 High Paymob for WooCommerce Plugin paymob-for-woocommerce Broken Access Control No login needed ≤ 4.1.2 CVE-2026-56025 Patchstack
8.8 High Abandoned Cart Pro for WooCommerce Plugin woocommerce-abandon-cart-pro Privilege Escalation ≤ 10.4.0 Fixed in 10.4.1 CVE-2026-56010 Patchstack
8.3 High APIExperts Square for WooCommerce Plugin woosquare Information Disclosure Sensitive Data Exposure No login needed ≤ 4.7.3 Fixed in 4.7.4 CVE-2026-54848 Patchstack
7.1 High Advanced Order Export For WooCommerce Plugin woo-order-export-lite Cross-Site Scripting No login needed ≤ 4.0.9 Fixed in 4.0.10 CVE-2026-56042 Patchstack
7.5 High InPost PL Plugin inpost-for-woocommerce Broken Access Control Unauthenticated WooCommerce Order Parcel-Locker Hijacking No login needed < 1.9.1 Fixed in 1.9.1 CVE-2026-9702 WPScan
7.1 High Ultimate WooCommerce Auction Pro Plugin Cross-Site Scripting Reflected XSS via uwa_manage_auctions No login needed ≤ 2.4.5 CVE-2026-4259 WPScan
7.6 High MultiLoca Plugin woocommerce-multi-locations-inventory-management Privilege Escalation ≤ 4.2.15 Fixed in 4.2.16 CVE-2026-39546 Patchstack
8.5 High WooCommerce Frontend Manager – Ultimate Plugin wc-frontend-manager-ultimate SQL Injection Ultimate plugin < 6.7.7 - SQL Injection < 6.7.7 Fixed in 6.7.7 CVE-2026-22335 Patchstack
7.5 High Woocommerce Book Price Plugin woo-book-price Path Traversal Arbitrary File Download No login needed ≤ 1.3 CVE-2026-22334 Patchstack
7.5 High WordPress & WooCommerce Scraper Plugin, Import Data from Any Site Plugin wp_scraper Path Traversal Arbitrary File Download No login needed ≤ 1.0.7 CVE-2025-69131 Patchstack
7.5 High WooCommerce POS Plugin woocommerce-pos Broken Access Control No login needed ≤ 1.8.14 Fixed in 1.9.0 CVE-2026-52711 Patchstack
7.1 High Min Max Step Quantity Limits Manager for WooCommerce Plugin product-quantity-for-woocommerce Cross-Site Scripting Reflected Cross Site Scripting (XSS) No login needed ≤ 5.2.2 Fixed in 5.2.3 CVE-2026-39437 Patchstack
7.5 High ABC Crypto Checkout Plugin payerurl-crypto-currency-payment-gateway-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 1.8.2 Fixed in 1.8.3 CVE-2026-52695 Patchstack
7.5 High Signature Add-On for WooCommerce Plugin woocommerce-digital-signature Information Disclosure Sensitive Data Exposure No login needed ≤ 2.0 Fixed in 2.0.1 CVE-2026-52694 Patchstack
7.5 High Upsell Order Bump Offer for WooCommerce Plugin upsell-order-bump-offer-for-woocommerce Price Manipulation No login needed ≤ 3.1.4 Fixed in 3.1.5 CVE-2026-49110 Patchstack
8.2 High Hippoo Mobile App for WooCommerce Plugin hippoo Broken Access Control No login needed ≤ 1.9.5 Fixed in 1.9.6 CVE-2026-49065 Patchstack
7.5 High WPC Product Options for WooCommerce Plugin wpc-product-options Path Traversal Arbitrary File Download No login needed ≤ 3.2.1 Fixed in 3.2.2 CVE-2026-49061 Patchstack
7.5 High WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Plugin print-invoices-packing-slip-labels-for-woocommerce Information Disclosure Sensitive Data Exposure No login needed ≤ 4.9.4 Fixed in 4.9.5 CVE-2026-49056 Patchstack
7.5 High WPC Product Bundles for WooCommerce Plugin woo-product-bundle Broken Access Control No login needed ≤ 8.5.3 Fixed in 8.5.4 CVE-2026-48883 Patchstack
7.5 High Montonio for WooCommerce Plugin montonio-for-woocommerce Broken Access Control No login needed ≤ 10.1.2 Fixed in 10.1.3 CVE-2026-48873 Patchstack
7.5 High Email Marketing for WooCommerce by Omnisend Plugin omnisend-connect Authentication Bypass Broken Authentication No login needed ≤ 1.18.0 Fixed in 1.18.1 CVE-2026-42668 Patchstack
8.2 High AI Product Search for WooCommerce – Motive Commerce Search Plugin motive-commerce-search Broken Access Control Motive Commerce Search plugin <= 1.38.2 - Broken Access Control No login needed ≤ 1.38.2 Fixed in 1.38.3 CVE-2026-42664 Patchstack
7.5 High Redsys for WooCommerce Light Plugin woo-redsys-gateway-light Broken Access Control No login needed ≤ 7.0.0 Fixed in 7.0.1 CVE-2026-40741 Patchstack
7.2 High Advanced Product Fields (Product Addons) for WooCommerce Plugin advanced-product-fields-for-woocommerce PHP Object Injection ≤ 1.6.19 Fixed in 1.6.20 CVE-2026-39499 Patchstack
7.2 High WooCommerce PDF Invoices & Packing Slips Plugin woocommerce-pdf-invoices-packing-slips PHP Object Injection < 5.9.0 Fixed in 5.9.0 CVE-2026-39472 Patchstack
7.2 High WooCommerce Cart Abandonment Recovery Plugin woo-cart-abandonment-recovery Privilege Escalation < 2.1.0 Fixed in 2.1.0 CVE-2026-39470 Patchstack
7.2 High CTX Feed Plugin webappick-product-feed-for-woocommerce PHP Object Injection ≤ 6.6.26 Fixed in 6.6.27 CVE-2026-39434 Patchstack
7.1 High WooCommerce Product Table Lite Plugin wc-product-table-lite Cross-Site Scripting No login needed ≤ 4.6.3 Fixed in 4.6.4 CVE-2026-34902 Patchstack
7.5 High Event Tickets Manager for WooCommerce Plugin event-tickets-manager-for-woocommerce Broken Access Control No login needed ≤ 1.5.3 Fixed in 1.5.4 CVE-2026-34898 Patchstack
7.5 High IDPay Payment Gateway for Woocommerce Plugin woo-idpay-gateway Information Disclosure Sensitive Data Exposure No login needed ≤ 2.2.5 CVE-2026-34891 Patchstack
8.1 High Recover Exit For WooCommerce Plugin recoverexit-for-woocommerce Local File Inclusion Unauthenticated Local File Inclusion via 'tpf' Parameter No login needed ≤ 1.0.3 CVE-2026-9662 Wordfence
7.1 High Wallet System for WooCommerce Plugin wallet-system-for-woocommerce Authentication Bypass Broken Authentication ≤ 2.7.5 Fixed in 2.7.6 CVE-2026-42654 Patchstack
8.8 High WooCommerce Infinite Scroll and Ajax Pagination Plugin PHP Object Injection Authenticated (Subscriber+) PHP Object Injection ≤ 1.8 CVE-2025-11993 Wordfence
8.6 High Eupago Gateway For Woocommerce Plugin eupago-gateway-for-woocommerce Broken Access Control Unauthenticated Arbitrary Refund Initiation No login needed < 4.7.2 Fixed in 4.7.2 CVE-2026-7862 WPScan
7.1 High Woocommerce Envato Affiliates Plugin wooenvato Broken Access Control Settings Change ≤ 1.2.1 CVE-2025-14361 Patchstack
7.5 High Smart Coupons for WooCommerce Plugin wt-smart-coupons-for-woocommerce Broken Access Control No login needed < 2.3.0 Fixed in 2.3.0 CVE-2026-45438 Patchstack
8.2 High WooCommerce PayPal Payments Plugin woocommerce-paypal-payments Broken Access Control Missing Authorization to Unauthenticated Order Manipulation and Information Disclosure No login needed ≤ 4.0.1 CVE-2026-9284 Wordfence
7.6 High YITH WooCommerce Product Add-Ons Plugin yith-woocommerce-product-add-ons SQL Injection ≤ 4.29.0 Fixed in 4.29.1 CVE-2026-42383 Patchstack
7.5 High Creative Mail – Easier WordPress & WooCommerce Email Marketing Plugin creative-mail-by-constant-contact SQL Injection Easier WordPress & WooCommerce Email Marketing <= 1.6.9 - Unauthenticated SQL Injection via 'checkout_uuid' Parameter No login needed ≤ 1.6.9 CVE-2026-3985 Wordfence
7.5 High Funnel Builder for WooCommerce Checkout Plugin funnel-builder Broken Access Control Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX No login needed < 3.15.0.3 Fixed in 3.15.0.3 CVE-2026-47100 VulnCheck
7.5 High Fortis For WooCommerce Plugin fortis-for-woocommerce Information Disclosure Sensitive API Key Disclosure No login needed < 1.3.1 Fixed in 1.3.1 CVE-2025-15609 WPScan
8.2 High Membership Plugin membership-for-woocommerce SQL Injection WordPress Plugin Supsystic Membership 1.4.7 SQL Injection via sidx No login needed 1.4.7 CVE-2020-37244 VulnCheck
8.1 High FOX – Currency Switcher Professional for WooCommerce Plugin woocommerce-currency-switcher Broken Access Control Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Configuration Deletion ≤ 1.4.5 CVE-2026-4094 Wordfence

About this data

Where it comes from
Each row is a record from the CVE List, published by the organization that handled the report: most often Wordfence, Patchstack or WPScan. The CVE ID links to that publisher's advisory.
What is included
CVEs published since January 1, 2024 for WordPress core, plugins and themes, premium ones included. Vulnerabilities that never received a CVE ID are not listed, and rejected CVEs are removed.
Severity
The CVSS 3.1 base score set by the publisher, or by CISA when the publisher gave none. "No login needed" means the score assumes an attacker without an account.
Affected versions
The range the publisher marked as vulnerable. When the record also names the first fixed release, it is shown under the range. If your version is newer than every affected one, that CVE does not apply to you.
Updates
Every day, after the CVE List publishes its end-of-day changes.

This website uses cookies to enhance your browsing experience and ensure the site functions properly. By continuing to use this site, you acknowledge and accept our use of cookies.

Accept All Accept Required Only